After Splunk for VMware beta, it no longer use vMA.
My apologies, to clearify: Splunk/vMA: How does it work with VMware's SDR.
Question is extremely unclear.
Splunk collect all the logs associated with hosts as DRS does its job and we collect metrics per host and per VM per normal. The vMA doesn’t move around due to DRS.